cbcvebase.
CVE-2023-54146
published 2025-12-24

CVE-2023-54146: In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fix memory…

PriorityP417medium6.4
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"), freeing image->elf_headers in the error path of crash_load_segments() is not needed because kimage_file_post_load_cleanup() will take care of that later. And not clearing it could result in a double-free. Drop the superfluous vfree() call at the error path of crash_load_segments().

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 23cf39dccf7653650701a6f39b119e9116a27f1a < 4c71a552b97fb4f46eb300224434fe56fcf4f2544c71a552b97fb4f46eb300224434fe56fcf4f254
linuxlinux>= 5.15.46 < 5.15.875.15.87
linuxlinux>= 5.17.14 < 5.185.18
linuxlinux>= 5.18.3 < 5.195.19
linuxlinux>= 8765a423a87d74ef24ea02b43b2728fe4039f248 < 554a880a1fff46dd5a355dec21cd77d542a0ddf2554a880a1fff46dd5a355dec21cd77d542a0ddf2
linuxlinux>= b3e34a47f98974d0844444c5121aaff123004e57 < fbdbf8ac333d3d47c0d9ea81d7d445654431d100fbdbf8ac333d3d47c0d9ea81d7d445654431d100
linuxlinux>= b3e34a47f98974d0844444c5121aaff123004e57 < 5bd3c7abeb69fb4133418b846a1c6dc11313d6f05bd3c7abeb69fb4133418b846a1c6dc11313d6f0
linuxlinux>= b3e34a47f98974d0844444c5121aaff123004e57 < d00dd2f2645dca04cf399d8fc692f3f69b6dd996d00dd2f2645dca04cf399d8fc692f3f69b6dd996
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 5.15.875.15.87
linuxlinux_kernel>= 5.16.0 < 6.0.196.0.19
linuxlinux_kernel>= 5.19.0 < 6.1.56.1.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.